git: 9cf774a577ab - main - cxgbe: Add a sysctl/tunable to control KTLS offload of AES-CBC cipher suites

From: John Baldwin <jhb_at_FreeBSD.org>
Date: Wed, 30 Sep 2026 20:53:46 UTC
The branch main has been updated by jhb:

URL: https://cgit.FreeBSD.org/src/commit/?id=9cf774a577abbe28e03a849d1ec25f47827f07e6

commit 9cf774a577abbe28e03a849d1ec25f47827f07e6
Author:     John Baldwin <jhb@FreeBSD.org>
AuthorDate: 2026-09-30 20:50:12 +0000
Commit:     John Baldwin <jhb@FreeBSD.org>
CommitDate: 2026-09-30 20:50:12 +0000

    cxgbe: Add a sysctl/tunable to control KTLS offload of AES-CBC cipher suites
    
    Disable these by default as they are less efficient and rarely used.
    
    Sponsored by:   Chelsio Communications
---
 sys/dev/cxgbe/crypto/t6_kern_tls.c |  7 ++++---
 sys/dev/cxgbe/crypto/t7_kern_tls.c |  7 ++++---
 sys/dev/cxgbe/offload.h            |  1 +
 sys/dev/cxgbe/t4_main.c            | 11 ++++++++++-
 4 files changed, 19 insertions(+), 7 deletions(-)

diff --git a/sys/dev/cxgbe/crypto/t6_kern_tls.c b/sys/dev/cxgbe/crypto/t6_kern_tls.c
index 584e5015acfa..1ebe536b4a43 100644
--- a/sys/dev/cxgbe/crypto/t6_kern_tls.c
+++ b/sys/dev/cxgbe/crypto/t6_kern_tls.c
@@ -383,6 +383,8 @@ t6_tls_tag_alloc(if_t ifp, union if_snd_tag_alloc_params *params,
 	int atid, error, explicit_iv_size, keyid, mac_first;
 
 	tls = params->tls.tls;
+	vi = if_getsoftc(ifp);
+	sc = vi->adapter;
 
 	/* Only TLS 1.1 and TLS 1.2 are currently supported. */
 	if (tls->params.tls_vmajor != TLS_MAJOR_VER_ONE ||
@@ -410,6 +412,8 @@ t6_tls_tag_alloc(if_t ifp, union if_snd_tag_alloc_params *params,
 		default:
 			return (EPROTONOSUPPORT);
 		}
+		if (!sc->tlst.cbc)
+			return (EPROTONOSUPPORT);
 		explicit_iv_size = AES_BLOCK_LEN;
 		mac_first = 1;
 		break;
@@ -431,9 +435,6 @@ t6_tls_tag_alloc(if_t ifp, union if_snd_tag_alloc_params *params,
 		return (EPROTONOSUPPORT);
 	}
 
-	vi = if_getsoftc(ifp);
-	sc = vi->adapter;
-
 	tlsp = alloc_tlspcb(ifp, vi, M_WAITOK);
 
 	atid = alloc_atid(sc, tlsp);
diff --git a/sys/dev/cxgbe/crypto/t7_kern_tls.c b/sys/dev/cxgbe/crypto/t7_kern_tls.c
index f01a346644af..35342399b468 100644
--- a/sys/dev/cxgbe/crypto/t7_kern_tls.c
+++ b/sys/dev/cxgbe/crypto/t7_kern_tls.c
@@ -160,6 +160,8 @@ t7_tls_tag_alloc(struct ifnet *ifp, union if_snd_tag_alloc_params *params,
 	uint32_t flowid;
 
 	tls = params->tls.tls;
+	vi = if_getsoftc(ifp);
+	sc = vi->adapter;
 
 	/* TLS 1.1 through TLS 1.3 are currently supported. */
 	if (tls->params.tls_vmajor != TLS_MAJOR_VER_ONE ||
@@ -187,6 +189,8 @@ t7_tls_tag_alloc(struct ifnet *ifp, union if_snd_tag_alloc_params *params,
 		default:
 			return (EPROTONOSUPPORT);
 		}
+		if (!sc->tlst.cbc)
+			return (EPROTONOSUPPORT);
 		iv_size = AES_BLOCK_LEN;
 		mac_first = 1;
 		break;
@@ -212,9 +216,6 @@ t7_tls_tag_alloc(struct ifnet *ifp, union if_snd_tag_alloc_params *params,
 		return (EPROTONOSUPPORT);
 	}
 
-	vi = if_getsoftc(ifp);
-	sc = vi->adapter;
-
 	tlsp = alloc_tlspcb(ifp, vi, M_WAITOK);
 
 	/*
diff --git a/sys/dev/cxgbe/offload.h b/sys/dev/cxgbe/offload.h
index d63accf86e2a..d0508ada2fcb 100644
--- a/sys/dev/cxgbe/offload.h
+++ b/sys/dev/cxgbe/offload.h
@@ -229,6 +229,7 @@ struct iw_tunables {
 };
 
 struct tls_tunables {
+	int cbc;
 	int inline_keys;
 	union {
 		struct {
diff --git a/sys/dev/cxgbe/t4_main.c b/sys/dev/cxgbe/t4_main.c
index 27aa2c56d9ec..c91120c85e07 100644
--- a/sys/dev/cxgbe/t4_main.c
+++ b/sys/dev/cxgbe/t4_main.c
@@ -748,11 +748,16 @@ TUNABLE_INT("hw.cxgbe.cop_managed_offloading", &t4_cop_managed_offloading);
  */
 static int t4_kern_tls = 0;
 SYSCTL_INT(_hw_cxgbe, OID_AUTO, kern_tls, CTLFLAG_RDTUN, &t4_kern_tls, 0,
-    "Enable KERN_TLS mode for T6 adapters");
+    "Enable KERN_TLS mode for T6+ adapters");
 
 SYSCTL_NODE(_hw_cxgbe, OID_AUTO, tls, CTLFLAG_RD | CTLFLAG_MPSAFE, 0,
     "cxgbe(4) KERN_TLS parameters");
 
+static int t4_tls_cbc = 0;
+SYSCTL_INT(_hw_cxgbe_tls, OID_AUTO, cbc, CTLFLAG_RDTUN,
+    &t4_tls_cbc, 0,
+    "Enable offload of AES-CBC cipher suites.");
+
 static int t4_tls_inline_keys = 0;
 SYSCTL_INT(_hw_cxgbe_tls, OID_AUTO, inline_keys, CTLFLAG_RDTUN,
     &t4_tls_inline_keys, 0,
@@ -6274,6 +6279,7 @@ set_params__post_init(struct adapter *sc)
 
 #ifdef KERN_TLS
 	if (is_ktls(sc)) {
+		sc->tlst.cbc = t4_tls_cbc;
 		sc->tlst.inline_keys = t4_tls_inline_keys;
 		if (t4_kern_tls != 0 && is_t6(sc)) {
 			sc->tlst.combo_wrs = t4_tls_combo_wrs;
@@ -8251,6 +8257,9 @@ t4_sysctls(struct adapter *sc)
 		    CTLFLAG_RD | CTLFLAG_MPSAFE, NULL, "KERN_TLS parameters");
 		children = SYSCTL_CHILDREN(oid);
 
+		SYSCTL_ADD_INT(ctx, children, OID_AUTO, "cbc",
+		    CTLFLAG_RW, &sc->tlst.cbc, 0,
+		    "Enable offload of AES-CBC cipher suites.");
 		SYSCTL_ADD_INT(ctx, children, OID_AUTO, "inline_keys",
 		    CTLFLAG_RW, &sc->tlst.inline_keys, 0, "Always pass TLS "
 		    "keys in work requests (1) or attempt to store TLS keys "